The highest priority IMHO is security . Given how a targeted email can reach someone wherever they are (and spam can conceal mass exploits), frequent security updates are the wrong mindset. The mindset of one necessary security update should be, OMG, we messed up badly, we need to fix and mitigate, and immediately figure out how never to need another security update, ever again. Web browsers, OTOH, are hopeless for s…
It literally could be a simple ASN lookup, and you would prevent 99% of targeted phishing emails.
Nobody in the world uses some random domain.trade to send emails as company.com ffs.
Microsoft is kind of not giving a damn about security and I dont understand why they do not invest in Outlook security that much. To me this is straight up offensive how they behave.
How can it be that a VBA exploit from 2003 can still compromise an updated system in 2023?